cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2092
Views
6
Helpful
10
Replies

expressway certificate already expired and webpage not accessible

eliranb7
Level 1
Level 1

Hi

the expressway's server certificate has been expired last week.
when trying to access the expressway's webpage to upload the new certificate ,the browser certificate error shows,

and if im hitting the advanced button in order to continue, the page gets an error.

tried it with several browsers, but with no luck.

any ideas ?
maybe there is an option to upload the certificate through CLI ?
thanks

3 Accepted Solutions

Accepted Solutions

Login to expressway using WINSCP, make sure you use root credentials and delete the expired certificate pem. Restart the expressway and you will be able to access the webpage.

Then generate the CSR and get the CSR signed by a CA and upload the certificate.



Response Signature


View solution in original post

As mentioned up, login to expressway using WinSCP as the root credential

Go to persistent folder>certs> delete the server.pem certificate 

Restart the Expressway then you will be able to access it

View solution in original post

Djeten
Level 1
Level 1

I have the same issue. Logging into the webinterface fails, logging in to CLI through the console with admin credentials and root credentials works. 

Logging in with winscp fails with both accounts.

Can I remove the certificate from CLI?

View solution in original post

10 Replies 10

Login to expressway using WINSCP, make sure you use root credentials and delete the expired certificate pem. Restart the expressway and you will be able to access the webpage.

Then generate the CSR and get the CSR signed by a CA and upload the certificate.



Response Signature


As mentioned up, login to expressway using WinSCP as the root credential

Go to persistent folder>certs> delete the server.pem certificate 

Restart the Expressway then you will be able to access it

eliranb7
Level 1
Level 1

works like a charm!

Thanks a lot !

Djeten
Level 1
Level 1

I have the same issue. Logging into the webinterface fails, logging in to CLI through the console with admin credentials and root credentials works. 

Logging in with winscp fails with both accounts.

Can I remove the certificate from CLI?

Yes it can be removed from CLI. When connected as root you can use normal Unix style commands, like ls to list files or rm to remove files or folders if that is what you want. If you do a ls -la persistent/certs/ you will see the content of the folder where the certificate is stored, then you can do a rm ls -la persistent/certs/server.pem to remove the cert.



Response Signature


this did not help...

I deleted the server.pem certificate and rebooted the expressway, but I still can't log in to the web gui

Djeten_0-1725545405067.png

Djeten_1-1725545535884.png

 

So then there is something else that is your problem. Have you worked with TAC on this issue?

Silly question, do you have the admin account set to allow Web access?

image.png



Response Signature


The account has worked before, so yes, the admin user has web access.

To be sure, I created a new admin user in the CLI, with webaccess, but I get the same error when I try to log in:

Djeten_0-1725613068740.png

 

Sounds like you’ll need to reach out to TAC on this.



Response Signature


@Djeten Your issue isn’t the same as the OP.  If I’m not mistaken you have another post on this. Your problem is related too not being able to login, that’s not related to certificates on the Expressway.

Edit: As I remember you have a post on your problem. https://community.cisco.com/t5/unified-communications-infrastructure/expressway-c-can-t-log-in-to-webinterface-anymore/td-p/5162513

This is not related to the problem the OP of this post has. Suggest that you continue your troubleshooting on your post.



Response Signature